Critical 'AgentForger' Flaw in ChatGPT Lets Attackers Hijack AI Agents via Phishing Link, OpenAI Issues Patch
Summary
A critical flaw dubbed 'AgentForger' in ChatGPT's Workspace Agents builder allows attackers to hijack AI agents via a single phishing link, silently connecting to victims' Outlook, Gmail, Slack, and Teams accounts while installing persistent attacker-controlled schedules — OpenAI patches the vulnerability within four days, but researchers warn the full damage potential, including data harvesting and business email compromise, has yet to be revealed.
Key Points
- A critical vulnerability dubbed 'AgentForger' is discovered in OpenAI's ChatGPT Workspace Agents builder, allowing attackers to forge an entire autonomous AI agent by embedding malicious instructions into a phishing URL, which automatically executes when a logged-in victim clicks the link.
- The forged agent silently connects to the victim's pre-authorized services like Outlook, Gmail, Slack, and Teams, disables approval gates for sensitive actions, and installs recurring five-minute schedules, effectively creating a persistent attacker-controlled operator inside the organization's trust boundary.
- OpenAI patches the vulnerability within four days of disclosure on June 4, 2026, but researchers warn that Part 2 will reveal the full blast radius of the attack, including organizational reconnaissance, sensitive data harvesting, user impersonation, and business email compromise.